PHP Object Injection Vulnerability in FacturaScripts by NeoRazorX
CVE-2026-104905

6.1MEDIUM

Key Information:

Vendor

Neorazorx

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104905?

FacturaScripts versions prior to 2026.7 are vulnerable to a PHP object injection flaw located in the WidgetSelect::processFormData() function. This vulnerability allows authenticated attackers to exploit the unserialize() function on unfiltered raw POST data, especially for multiple-select fields. By submitting a specially crafted serialized XLSXWriter object, attackers can invoke its __destruct() method, leading to the deletion of arbitrary files such as config.php. This results in potential denial of service and may facilitate unauthorized hijacking of application installations.

Affected Version(s)

facturascripts 2025.7 < 2026.7

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alisher Qarshibayev
VulnCheck
.